A critical privilege escalation flaw (CVSS 9.8) in the Divi Membership WordPress plugin, versions up to and including 2.2.0, lets unauthenticated attackers register a new administrator account and log in as that account, which gives them full control of the site.
What Is It
CVE-2026-19652 is a privilege escalation vulnerability (CWE-269) in DiviEngine's Divi Membership plugin. The bug is in the dmem_form_submit_handler() function. To decide the role for a new user, the function loops through every WordPress role and calls password_verify() against a bcrypt hash that the attacker supplies in the form_id POST parameter. It does not validate the role or check it against a list of allowed roles.
An attacker can compute a bcrypt hash of the string administrator on their own machine and submit it as form_id. That registers a new account with the administrator role. If the attacker also submits auto_login=on, they are logged in as that administrator in the same request.
The exploit needs a WordPress nonce. However, the nonce appears publicly on any page that shows the Divi Membership registration form, so any unauthenticated visitor can get it.
Why It Matters
- CVSS 3.1: 9.8 (CRITICAL),
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - No authentication or user interaction is needed. The attack works over the network and is simple to carry out.
- Impact: an attacker gets full site takeover through a newly created administrator account.
- Nonce protection doesn't help here. The required nonce is shown on public pages, so it does not stop the attack.
This CVE is not currently listed in CISA's Known Exploited Vulnerabilities (KEV) Catalog. The supplied data does not confirm active exploitation, and there is no CISA required action or deadline.
What's Vulnerable
- Vendor: DiviEngine
- Product: Divi Membership (WordPress plugin)
- Affected versions: all versions up to and including 2.2.0
Any site with an affected version that shows the Divi Membership registration form should be treated as exposed.
Patch Status
The NVD record lists versions up to and including 2.2.0 as affected. It does not name a specific fixed release. Administrators should check DiviEngine's changelog for a release that fixes this issue, update when one is available, and audit their sites for administrator accounts they don't recognize. Wordfence published the advisory, and the NVD status is currently "Deferred."